2.1
CVSSv2

CVE-2013-0162

Published: 01/03/2013 Updated: 13/02/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The diff_pp function in lib/gauntlet_rubyparser.rb in the ruby_parser gem 3.1.1 and previous versions for Ruby allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.

Vulnerable Product Search on Vulmon Subscribe to Product

ryan davis ruby parser 2.2.0

ryan davis ruby parser 3.0.0.a6

ryan davis ruby parser 3.0.4

ryan davis ruby parser 3.0.0.a7

ryan davis ruby parser 3.0.1

ryan davis ruby parser 3.0.0

ryan davis ruby parser 3.0.0.a8

ryan davis ruby parser 3.0.0.a2

ryan davis ruby parser 2.0.1

ryan davis ruby parser 2.3.1

ryan davis ruby parser 3.0.0.a5

ryan davis ruby parser 3.0.0.a3

ryan davis ruby parser 2.0.3

ryan davis ruby parser 3.0.3

ryan davis ruby parser 2.0.6

ryan davis ruby parser 1.0.0

ryan davis ruby parser 3.0.2

ryan davis ruby parser 3.0.0.a9

ryan davis ruby parser 2.3.0

ryan davis ruby parser 3.0.0.a10

ryan davis ruby parser

ryan davis ruby parser 2.0.0

ryan davis ruby parser 3.1.0

ryan davis ruby parser 2.0.2

ryan davis ruby parser 2.0.5

ryan davis ruby parser 3.0.0.a1

ryan davis ruby parser 2.0.4

ryan davis ruby parser 3.0.0.a4

ryan davis ruby parser 2.1.0

Vendor Advisories

Debian Bug report logs - #701637 CVE-2013-0162 Package: ruby-parser; Maintainer for ruby-parser is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Source for ruby-parser is src:ruby-parser (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 25 Feb 20 ...
Synopsis Important: Subscription Asset Manager 12 update Type/Severity Security Advisory: Important Topic Red Hat Subscription Asset Manager 12, which fixes several securityissues, multiple bugs, and adds various enhancements, is now availableThe Red Hat Security Response Team has rated this update as ha ...
Synopsis Moderate: Red Hat OpenShift Enterprise 111 update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Enterprise 111 is now availableThe Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerability Scoring System (CVSS) base scores, ...